H̶m̶m̶,̶ ̶t̶h̶i̶s̶ ̶w̶i̶l̶l̶ ̶n̶o̶t̶ ̶f̶l̶y̶ ̶:̶)̶ ̶ I̶'̶m̶ ̶p̶r̶e̶t̶t̶y̶ ̶s̶u̶r̶e̶ ̶y̶o̶u̶ ̶c̶a̶n̶'̶t̶ ̶j̶u̶s̶t̶ ̶s̶t̶r̶i̶p̶ ̶t̶h̶e̶ ̶l̶i̶c̶e̶n̶s̶e̶ ̶o̶f̶ ̶a̶ ̶s̶o̶f̶t̶w̶a̶r̶e̶ ̶a̶n̶d̶ ̶r̶e̶l̶e̶a̶s̶e̶ ̶i̶t̶ ̶u̶n̶d̶e̶r̶ ̶t̶h̶e̶ ̶t̶e̶r̶m̶s̶ ̶y̶o̶u̶ ̶w̶i̶s̶h̶ ̶i̶t̶ ̶h̶a̶d̶.̶ ̶ ̶h̶t̶t̶p̶s̶:̶/̶/̶c̶o̶d̶e̶.̶v̶i̶s̶u̶a̶l̶s̶t̶u̶d̶i̶o̶.̶c̶o̶m̶/̶l̶i̶c̶e̶n̶s̶e̶ ̶ ̶"̶Y̶o̶u̶ ̶m̶a̶y̶ ̶n̶o̶t̶.̶.̶.̶ ̶s̶h̶a̶r̶e̶,̶ ̶p̶u̶b̶l̶i̶s̶h̶,̶ ̶r…
The problem is they’ve taken a commit that was obviously made in error, and used that to justify the IP contained within that commit being MIT licensed. Sure, this might be legally sound. But it’s certainly scummy. Especially when you consider it’s acting against the wishes of the team that has been working hard over the past years to make a product loved by so many.
There’s no proprietary algorithm being described and I’m guessing that those URLs respond with 200 OK without any authentication of where the request is coming from, which says to me the host thinks it’s okay to send me that data. (On mobile or I would check.)
Would it still be a problem if it were forked and the JSON key names were changed or some other alternative method of configuring the URLs were used?
I would understand if the entire source file for interacting with the extension gallery were taken here, but just a config setting?! That says to me that I couldn’t write my own web browser with the default homepage set to Google without permission...
[0] https://github.com/Microsoft/vscode/commit/f1d0c1d88417f85ec...